Identity and Access Management on AWS: Designing and Implementing an AWS Organization
This course will explain the proper use of multiple accounts in AWS and how to manage multiple accounts using the Organizations feature and Service Control Policies in AWS.
What you'll learn
For small organizations, a single AWS account may be all that is required, but for many organizations, multiple accounts are a fact of life, whether for security, business/finance reasons, or due to mergers and acquisitions. Managing multiple accounts is a big challenge, but one for which AWS has provided tools. In this course, Identity and Access Management on AWS: Designing and Implementing an AWS Organization, you will gain the ability to manage multiple AWS accounts leveraging AWS tools and best practices. First, you will learn why multiple accounts may be needed, what the AWS Organizations feature is and how it can help in the management of those accounts, and the role of Organizational Units (OUs) in an Organization. Next, you will discover how to leverage Service Control Policies (SCPs) to gain finer-grained control over what IAM accounts can do within an AWS account. Finally, you will explore how to monitor an Organization, leverage Security Hub, and see how the Landing Zone concept can be used to deploy accounts according to best practices. When you’re finished with this course, you will have the skills and knowledge about AWS Organizations needed to effectively create, manage, and monitor multiple AWS accounts.
Table of contents
- Course Introduction 1m
- Globomantics Overview 1m
- IAM Review 5m
- Account Management 6m
- Intro to Organizations 6m
- Creating an Organization 6m
- Accounts 7m
- Demo 1: Starting with AWS Organizations 9m
- Accessing Created and Joined Accounts 3m
- Demo 2: Accessing the Created Member Account 7m
- Demo 3: Accessing the Joined Member Account 3m
- Account Removal 3m
- Organizational Units 4m
- Demo 4: Working with Organizational Units 6m
- Module Summary 1m
- Module Introduction 1m
- Trusted Access 3m
- Trusted Access Service Descriptions 10m
- Monitoring 3m
- Landing Zone Intro 2m
- Landing Zone: Multiple Core Accounts Overview 3m
- Landing Zone: Account Vending Machine 2m
- Landing Zone: User Accounts 2m
- Landing Zone: Security Baseline 2m
- Landing Zone: Notifications 3m
- Security Hub 3m
- Organizations Best Practices 9m
- Summary 1m